HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
OneDigital Investment Advisors LLC
bd_616a7eca5bff3650 · schema v1 · pii pii-v1
Full breach record for OneDigital Investment Advisors LLC →OneDigital Investment Advisors LLC notified the New Hampshire Attorney General of a data event involving its third-party vendors, Salesforce and Salesloft (Drift). Between August 12-18, 2025, an unauthorized actor accessed and copied customer data (names and SSNs) from the Drift application. Approximately 163 New Hampshire residents were affected. OneDigital engaged forensic specialists, notified regulators, and provided 12 months of credit monitoring via Experian. The incident did not compromise OneDigital's internal network.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_16dcd2a6a721552eWashington State AGfiled 2026-04-08Candidate
- bd_17257010d9a4d51aMaine State AGfiled 2026-04-08Verified
- bd_5a1b88518f9bfe89California State AGfiled 2026-04-08Verified
- bd_89c363698f4bb715Indiana State AGfiled 2026-04-08Verified
Show 3 more filings ↓Show fewer ↑up to 12d gap
- bd_a8e53b1611378d44Vermont State AGfiled 2026-04-08Verified
- bd_ed2c8dae469e2d8bTexas State AGfiled 2026-04-10(2d gap)Verified by operator
- bd_2634d621d74802adOregon State AGfiled 2026-04-20(12d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/onedigital-investment-advisors-20260408.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 8, 2026
- Raw hash
- 0a9229450e937e6a6d161ecf87d596c5ed5f39eb1e7cf0598cf7f7f15bc23861
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- OneDigital Investment Advisors LLCnorm: onedigital investment advisors
- Domain
- onedigital.com
Incident
- Discovered
- Aug 22, 2025
- Materiality determined
- —
- Notification sent
- Apr 8, 2026
- Affected individuals
- 163
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain CompromiseT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notified Office of the New Hampshire Attorney General Consumer Protection & Antitrust BureauProviding written notice of this incident to other applicable state regulators and the three major credit reporting agencies
- Third party
- via Salesforce / Salesloft (Drift)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 33 weeks(229 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.